Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-2188


Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. This vulnerability could allow an unauthenticated attacker to create a port mapping rule via a SOAP request and store a malicious JavaScript payload within that rule, which could result in an execution of the JavaScript payload when the rule is loaded.


Published

2024-03-05T13:15:07.203

Last Modified

2025-03-04T14:22:15.710

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tp-link archer_ax50_firmware 1.0.11 Yes
Hardware tp-link archer_ax50 - No

References